JSCEAL Malware Spread Through Fake Cryptocurrency Exchange Ads on Facebook

Summary
AhnLab reports that Facebook ads impersonating a cryptocurrency exchange distributed JSCEAL to Windows and macOS users in Korea. About 1,500 PC infections were confirmed over August and September 2026.
Key points
- The ads offered cryptocurrency rewards for installing an exchange program and redirected users to a fake exchange site.
- The site generated different installers by operating system: a BAT file for Windows and a PKG file for macOS.
- On Windows, the BAT file used PowerShell to download and run more code, create scheduled-task persistence, add a Microsoft Defender exclusion, and launch JSCEAL using Node.js.
- On macOS, the PKG installer downloaded scripts, prompted users for their account password, and sent system details and clipboard data to an external server.
- The macOS infection also registered a LaunchAgent to enable follow-up commands and execute additional JSCEAL payloads.
- AhnLab advises checking for suspicious scripts, persistence, Defender exclusions, credential prompts, and related execution traces; users should download exchange software only from official sites.
Article Details
- Attack Vectors
- Facebook ads promising cryptocurrency rewards led users to a site impersonating a cryptocurrency exchange.
- The site checked the visitor's operating system and generated a BAT installer for Windows or a PKG installer for macOS.
- On Windows, the BAT file used PowerShell to download and execute additional code. The malware added a Microsoft Defender exclusion, registered scheduled tasks, and used an embedded Node.js runtime to execute JSCEAL.
- On macOS, a script in the PKG installation process downloaded and ran another shell script. It prompted for the user's password, collected system and clipboard information, and registered a LaunchAgent for subsequent execution.
- Defensive Notes
- On Windows, review PowerShell execution and downloads, Microsoft Defender exclusions, scheduled tasks, the Users\Public\Desktop\Binance.LNK shortcut, and Node.js execution of JavaScript or V8 bytecode.
- On macOS, review installer-initiated shell scripts, unexpected password prompts and stored passwords, external transmission of system or clipboard data, LaunchAgents, and subsequent JavaScript execution.
- Download cryptocurrency exchange software from its official website rather than running BAT or PKG files from unknown sources. Stop and verify the source if installation unexpectedly requests a password.
MITRE ATT&CK
T1053.005 · Scheduled TaskThe Windows malware registered scheduled tasks for persistence and subsequent command retrieval.T1059.001 · PowerShellThe Windows BAT loader used PowerShell to download and execute additional code.T1059.004 · Unix ShellThe macOS PKG installation process downloaded and executed an additional shell script.T1059.007 · JavaScriptJSCEAL used an embedded Node.js runtime to execute JavaScript payloads.T1070.004 · File DeletionThe macOS installation process deleted temporary files after executing the downloaded script.T1105 · Ingress Tool TransferThe Windows loader downloaded additional code and a compressed file; the macOS installer downloaded an additional shell script.T1115 · Clipboard DataThe macOS script transmitted clipboard data to an external server.T1204.002 · Malicious FileUsers were induced to run a BAT or PKG file presented as a cryptocurrency exchange installer.T1543.001 · Launch AgentThe macOS infection registered a LaunchAgent to enable follow-up command execution.T1562.001 · Disable or Modify ToolsA Windows scheduled task added a Microsoft Defender exclusion to evade detection.
Malware
Vendors
Products
FacebookBeware of Malware infection in Facebook Ads Offering Cryptocurrency RewardsmacOSOver the past two months, JSCEAL infections have been confirmed on approximately 1,500 PCs in Korea, with both Windows and macOS systems included as Attack Targets.Microsoft DefenderWhen a scheduled task runs, it adds an exclusion to Microsoft Defender to evade detection and communicates with the C2 server to receive additional commands.Node.jsThis time, a case was confirmed in which the Node.Js-based malware JSCEAL was distributed through Facebook ads impersonating a cryptocurrency exchange.WindowsOver the past two months, JSCEAL infections have been confirmed on approximately 1,500 PCs in Korea, with both Windows and macOS systems included as Attack Targets.